The Indian Institute of Technology Bombay (IIT Bombay), founded in 1958 at Powai, Mumbai, is one of India's premier engineering and research institutions and one of the very few universities in this catalog that actually publishes a first-party, machine-readable API contract of its own. It operates no central developer portal and no institutional API programme, and there is no course catalog, registrar, open-data or research-computing API in public view. What it does run — and what almost every peer institution does not — is a live OpenAPI-described campus-life API, InstiApp, served from its own host at gymkhana.iitb.ac.in with an autogenerated 112-path specification, an institutional contact address and AGPL-3.0 source published by the Developers' Community. Alongside it sit two institution-operated identity surfaces: the Computer Centre's central OpenID Connect provider at sso.iitb.ac.in, which publishes a live discovery document and JWKS, and the Students' Gymkhana OAuth 2.0 Profiles service with ten documented consent scopes, access to which is restricted to applications hosted on Gymkhana infrastructure. The Central Library runs a DSpace institutional repository whose OAI-PMH endpoint is currently denied at the web-server layer. A fourth surface, the Institute Technical Council's SSO, is run by an IIT Bombay student body but on a domain the institution does not own, and is recorded as a tenant relationship rather than credited to the institution.
Indian Institute of Technology Bombay publishes 1 API on the APIs.io network: InstiApp API. Tagged areas include University, Higher Education, Education, India, and Institute of Technology.
The Indian Institute of Technology Bombay catalog on APIs.io includes 2 JSON-LD contexts and 1 Spectral governance ruleset.
Indian Institute of Technology Bombay’s developer surface includes API reference, documentation, support, and 14 more developer resources.
Regulatory Posture applies to this provider. Its tags matched the
Education & Research regime, so
Regulatory Posture carries 15 points of the composite.
If this regime is wrong for your business, say so on your
provider repo — the
applicability map is public and we will correct it.
Create-or-Update Ergonomics applies to this provider. This API accepts writes, so it
carries 10 points of the composite. It is scored from the published contracts
themselves: whether a caller can create-or-update in one call, whether the write accepts a key the caller already
holds, and whether the response says which branch ran. Without that, every write needs a search-and-branch in
front of it, and the first time that check is skipped a duplicate record is created.
Scored against the observed mean rather than raw — a provider at the catalog average is unchanged by this facet,
not penalised by it.
The six quality facets above are damped to 75 points between them,
because the conditional facet above carries the other
25. That is why each facet's contribution is shown against a damped
maximum: raising a quality facet moves the composite by 75% of its nominal
weight, not 100%. The full arithmetic is at apis.io/rating/.
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. Every facet and dimension name above is a link: it opens that measurement's own page — what it means, the exact checks that feed it, how the whole catalog distributes on it, and the providers at the top of it. This rating is computed from github.com/api-evangelist/iit-bombay: open an issue to ask a question, or submit a pull request to add artifacts.
Submit an artifact on GitHub — free →Manage your own listing — the Influence plan, $499/mo →
IIT Bombay's campus-life API and the single largest first-party programmable surface the institution operates. 112 paths and 164 operations over student bodies and their role gr...
The IIT Bombay Computer Centre's central identity provider, and the credential every institutional service sits behind. It publishes a live OpenID Connect Discovery 1.0 document...
An OAuth 2.0 (RFC 6749) identity and profile API operated by the IIT Bombay Students' Gymkhana, with ten separately-consented scopes covering SSO id, name, picture, sex, LDAP us...
The IIT Bombay Central Library institutional repository, running DSpace over theses, journal articles and conference papers. Its OAI-PMH 2.0 harvesting interface is the surface ...
A session-based Single Sign-On service maintained by the Institute Technical Council for authenticating IIT Bombay users in student and club projects. A redirect-based ssocall f...
aid: iit-bombay
name: Indian Institute of Technology Bombay
x-type: university
x-category: Institute of Technology
description: 'The Indian Institute of Technology Bombay (IIT Bombay), founded in 1958 at Powai, Mumbai, is one of India''s
premier engineering and research institutions and one of the very few universities in this catalog that actually publishes
a first-party, machine-readable API contract of its own. It operates no central developer portal and no institutional API
programme, and there is no course catalog, registrar, open-data or research-computing API in public view. What it does run
— and what almost every peer institution does not — is a live OpenAPI-described campus-life API, InstiApp, served from its
own host at gymkhana.iitb.ac.in with an autogenerated 112-path specification, an institutional contact address and AGPL-3.0
source published by the Developers'' Community. Alongside it sit two institution-operated identity surfaces: the Computer
Centre''s central OpenID Connect provider at sso.iitb.ac.in, which publishes a live discovery document and JWKS, and the
Students'' Gymkhana OAuth 2.0 Profiles service with ten documented consent scopes, access to which is restricted to applications
hosted on Gymkhana infrastructure. The Central Library runs a DSpace institutional repository whose OAI-PMH endpoint is
currently denied at the web-server layer. A fourth surface, the Institute Technical Council''s SSO, is run by an IIT Bombay
student body but on a domain the institution does not own, and is recorded as a tenant relationship rather than credited
to the institution.'
type: Index
deliveryModel:
model: saas
open_source: true
commercial: false
callable_host: true
label: Institution-hosted service · you call their endpoint · source is public
confidence: high
source:
- openapi/iit-bombay-instiapp-api-openapi.yml
- https://github.com/DevCom-IITB/instiapp-api
generated: '2026-08-30'
method: probed
accessModel:
pricing: free
onboarding: none
trial: false
try_now: true
public: true
label: Free · partially keyless
confidence: high
source:
- examples/iit-bombay-instiapp-examples.yml
generated: '2026-08-30'
method: probed
position: Producing
access: 1st-Party
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/iit-bombay.png
url: https://raw.githubusercontent.com/api-evangelist/iit-bombay/refs/heads/main/apis.yml
tags:
- University
- Higher Education
- Education
- India
- Institute of Technology
- Research
- Identity
- Single Sign-On
- OpenID Connect
- Campus Life
- Research Repository
- Open-Source
tags_raw:
- University
- Higher Education
- Education
- India
- Institute of Technology
- Research
- Identity
- Single Sign-On
- OpenID Connect
- Campus Life
- Research Repository
- Open Source
created: '2026-06-03'
modified: '2026-08-30'
specificationVersion: '0.23'
x-enrichment:
pipeline: pipeline-university.md
run: '2026-08-30'
operator_axis_settled: true
audit_baseline:
date: '2026-08-30'
institution_hosts:
- gymkhana.iitb.ac.in
- dspace.library.iitb.ac.in
tenant_hosts: []
verdicts:
institution: 2
unknown: 1
hostless: none
shared_contract: none
misbased: none
changes:
- 'ADDED the InstiApp API (x-operator: institution) — a first-party, live, OpenAPI-described surface on the institution''s
own host that this repo did not hold. The repo had no openapi/ directory at all before this run.'
- 'ADDED IITB Central SSO (x-operator: institution) — a live OpenID Connect discovery document and JWKS at sso.iitb.ac.in.
This is the identity-federation surface class the university pipeline names as a real and rarely-catalogued find.'
- 'RELABELLED the ITC Single Sign-On surface from unqualified to x-operator: tenant. It is run by an IIT Bombay student
council, but tech-iitb.org was registered 2024-10-02 through Hostinger and is not an institution-owned domain. The relationship
is kept, not deleted.'
- WITHDREW the claim that the DSpace OAI-PMH Identify verb returns a valid OAI-PMH 2.0 response. It no longer does; /oai/request
answers 403 at the Apache layer. Downgraded to unverified.
- 'REMOVED a mislabelled pointer: the DSpace surface carried "type: OpenAPI" pointing at an OAI-PMH ?verb=Identify URL,
which is neither an OpenAPI nor, now, reachable.'
no_vendor_contracts_added: true
apis:
- aid: iit-bombay:instiapp-api
name: InstiApp API
x-operator: institution
x-operator-evidence: servers[0].url is https://gymkhana.iitb.ac.in/instiapp/api — a host under the institution's own registrable
domain iitb.ac.in. info.contact.email is devcom@iitb.ac.in. The implementation is published by the institution's Developers'
Community at github.com/DevCom-IITB/instiapp-api under AGPL-3.0. The vanity host api.insti.app 301- redirects to gymkhana.iitb.ac.in/instiapp/,
so even the non-institutional-looking domain resolves to institution infrastructure. No vendor appears anywhere in the
contract.
description: IIT Bombay's campus-life API and the single largest first-party programmable surface the institution operates.
112 paths and 164 operations over student bodies and their role graphs (154 bodies live), institute events and calendar,
the news feed, hostel mess menus (22 messes), 427 named campus map locations with institute-map coordinates, a public
grievance register, a student marketplace, lost-and-found, achievements, and placement/internship blogs. A substantial
read surface answers with no credential at all; user-scoped and placement paths require a session. The specification is
autogenerated by drf-yasg from the live Django routes and is served at /docs/.
humanURL: https://gymkhana.iitb.ac.in/instiapp/api/docs/
baseURL: https://gymkhana.iitb.ac.in/instiapp/api
tags:
- Campus Life
- Event
- Students
- Open-Source
- Open Data
- Identity
tags_raw:
- Campus Life
- Events
- Students
- Open Source
- Open Data
- Identity
properties:
- type: OpenAPI
url: openapi/iit-bombay-instiapp-api-openapi.yml
- type: OpenAPIOriginal
url: openapi/_original/iit-bombay-instiapp-api-openapi.json
- type: APIReference
url: https://gymkhana.iitb.ac.in/instiapp/api/docs/
- type: JSONSchema
url: json-schema/iit-bombay-instiapp-schemas.json
- type: Examples
url: examples/iit-bombay-instiapp-examples.yml
- type: Vocabulary
url: vocabulary/iit-bombay-vocabulary.yml
- type: Rules
url: rules/iit-bombay-rules.yml
- type: Errors
url: errors/iit-bombay-problem-types.yml
- type: Lifecycle
url: lifecycle/iit-bombay-lifecycle.yml
- type: Authentication
url: authentication/iit-bombay-authentication.yml
- type: Conformance
url: conformance/iit-bombay-conformance.yml
- type: SourceCode
url: https://github.com/DevCom-IITB/instiapp-api
- type: TermsOfService
url: https://insti.app/tos.html
- type: Support
url: https://github.com/DevCom-IITB/instiapp-api/issues
- type: Website
url: https://insti.app/
- aid: iit-bombay:sso-oidc
name: IITB Central SSO — OpenID Connect
x-operator: institution
x-operator-evidence: Host sso.iitb.ac.in is under the institution's own registrable domain. The discovery document's issuer
is https://sso.iitb.ac.in itself. The sign-in page is branded "Computer Center, IIT Bombay". No vendor identity platform
is involved.
description: 'The IIT Bombay Computer Centre''s central identity provider, and the credential every institutional service
sits behind. It publishes a live OpenID Connect Discovery 1.0 document and a JWKS: issuer https://sso.iitb.ac.in, authorization,
token and userinfo endpoints, response_types_supported ["code"], token_endpoint_auth_methods_supported ["client_secret_basic"],
and a deliberately minimal scopes_supported of ["openid"]. Interactive sign-in is LDAP plus a second factor — TOTP, a
hardware credential, or SMS OTP. Client registration is not self-service; the Gymkhana developer documentation directs
external developers to the Computer Centre for IITB SSO integration.'
humanURL: https://sso.iitb.ac.in/
baseURL: https://sso.iitb.ac.in
tags:
- Identity
- Single Sign-On
- OpenID Connect
- Authentication
- Federation
properties:
- type: IdentityFederation
url: https://sso.iitb.ac.in/.well-known/openid-configuration
- type: JWKS
url: https://sso.iitb.ac.in/.well-known/jwks.json
- type: Authentication
url: authentication/iit-bombay-authentication.yml
- type: Scopes
url: scopes/iit-bombay-scopes.yml
- aid: iit-bombay:gymkhana-profiles
name: Gymkhana Profiles OAuth API
x-operator: institution
x-operator-evidence: Host gymkhana.iitb.ac.in is under iitb.ac.in. The implementation is published by the institution's
own student body at github.com/iitb-gymkhana/sso (GPL-3.0), whose declared homepage is this endpoint.
description: 'An OAuth 2.0 (RFC 6749) identity and profile API operated by the IIT Bombay Students'' Gymkhana, with ten
separately-consented scopes covering SSO id, name, picture, sex, LDAP username and e-mail, phone, campus address, student
record (roll number, department, course, joining and graduation year), alternate e-mails, and permission to send mail
on the user''s behalf. It is the only place in IIT Bombay''s public footprint where student-record fields are exposed
under explicit user consent. Access is restricted by policy: the documentation states that Profiles is intended only for
applications running on Gymkhana server infrastructure and that others may be deleted and blocked without notice. No RFC
8414 authorization-server metadata is published.'
humanURL: https://gymkhana.iitb.ac.in/profiles/doc/
baseURL: https://gymkhana.iitb.ac.in/profiles/
tags:
- Identity
- Authentication
- Profiles
- Students
tags_raw:
- Identity
- OAuth
- Authentication
- Profiles
- Students
properties:
- type: Documentation
url: https://gymkhana.iitb.ac.in/profiles/doc/
- type: Authentication
url: authentication/iit-bombay-authentication.yml
- type: Scopes
url: scopes/iit-bombay-scopes.yml
- type: SourceCode
url: https://github.com/iitb-gymkhana/sso
- type: GitHubOrganization
url: https://github.com/iitb-gymkhana
- aid: iit-bombay:dspace-oai-pmh
name: DSpace Institutional Repository (Central Library)
x-operator: institution
x-operator-evidence: Host dspace.library.iitb.ac.in is under the institution's own registrable domain and resolves to 103.21.126.134,
the same address as www.library.iitb.ac.in. DSpace is vendor software, but the deployment, the host and the content are
the institution's — the university pipeline's rule for OAI-PMH on an institution's own host.
description: 'The IIT Bombay Central Library institutional repository, running DSpace over theses, journal articles and
conference papers. Its OAI-PMH 2.0 harvesting interface is the surface of interest and it is NOT currently verifiable:
https://dspace.library.iitb.ac.in/oai/request returns 403 Forbidden from Apache with a browser User-Agent, an XML Accept
header and a same-host Referer, and its ErrorDocument 500s behind that. /jspui/ is 403 the same way, while /jspui/oai/request
renders a genuine DSpace error page, so the application is alive and it is the /oai path that is denied at the web-server
layer. /xmlui/OAI/request returns HTTP 200 with Content-Length 0 — a soft-200, not a response. The claim in this repo''s
June 2026 profile that the Identify verb returned a valid OAI-PMH 2.0 envelope has been withdrawn.'
humanURL: https://dspace.library.iitb.ac.in/
baseURL: https://dspace.library.iitb.ac.in/oai/request
tags:
- Research Repository
- OAI-PMH
- Open Access
- Library
- Research
- Metadata
x-liveness:
state: blocked
probed: '2026-08-30'
evidence:
- url: https://dspace.library.iitb.ac.in/
status: 200
note: meta-refresh to /jspui/
- url: https://dspace.library.iitb.ac.in/oai/request?verb=Identify
status: 403
- url: https://dspace.library.iitb.ac.in/jspui/
status: 403
- url: https://dspace.library.iitb.ac.in/jspui/oai/request?verb=Identify
status: 404
note: DSpace application error page
- url: https://dspace.library.iitb.ac.in/xmlui/OAI/request?verb=Identify
status: 200
note: Content-Length 0 — soft-200
properties:
- type: ResearchRepository
url: https://dspace.library.iitb.ac.in/
- type: Conformance
url: conformance/iit-bombay-conformance.yml
- aid: iit-bombay:itc-sso
name: ITC Single Sign-On
x-operator: tenant
x-operator-evidence: Operated by the Institute Technical Council, an IIT Bombay student body, but NOT on an institution-owned
host. tech-iitb.org was registered 2024-10-02 through Hostinger and resolves to 82.112.236.232 (Hostinger). The institution's
registrable domain is iitb.ac.in. Under the operator axis this is a student-body surface on a domain the institution does
not control — a real relationship, recorded as such, and not credited to the institution's own engineering.
description: A session-based Single Sign-On service maintained by the Institute Technical Council for authenticating IIT
Bombay users in student and club projects. A redirect-based ssocall flow returns an access id that the backend exchanges
via a getuserdata POST for user profile fields (name, roll number, department, degree, graduation year). Sessions last
one hour. No OpenID Connect discovery document is published; /.well-known/openid-configuration returns 404.
humanURL: https://sso.tech-iitb.org/docs/
baseURL: https://sso.tech-iitb.org/
tags:
- Identity
- Single Sign-On
- Authentication
- Students
properties:
- type: Documentation
url: https://sso.tech-iitb.org/docs/
- type: Authentication
url: authentication/iit-bombay-authentication.yml
- type: GitHubOrganization
url: https://github.com/Institute-Technical-Council
common:
- type: License
name: AGPL-3.0
url: https://github.com/DevCom-IITB/instiapp-api/blob/master/LICENSE
- type: Website
url: https://www.iitb.ac.in/
- type: APIReference
url: https://gymkhana.iitb.ac.in/instiapp/api/docs/
- type: Documentation
url: https://gymkhana.iitb.ac.in/profiles/doc/
- type: IdentityFederation
url: https://sso.iitb.ac.in/.well-known/openid-configuration
- type: ResearchRepository
url: https://dspace.library.iitb.ac.in/
- type: LibraryCatalog
url: https://www.library.iitb.ac.in/
- type: CourseCatalog
url: https://asc.iitb.ac.in/
- type: GitHubOrganization
url: https://github.com/DevCom-IITB
- type: Support
url: https://github.com/DevCom-IITB/instiapp-api/issues
- type: TermsOfService
url: https://www.iitb.ac.in/credits-disclaimer
- type: LinkedIn
url: https://www.linkedin.com/school/indian-institute-of-technology-bombay/
- type: DomainSecurity
url: security/iit-bombay-domain-security.yml
- type: Plans
url: plans/iit-bombay-plans-pricing.yml
- type: RateLimits
url: rate-limits/iit-bombay-rate-limits.yml
- type: FinOps
url: finops/iit-bombay-finops.yml
- type: Review
url: review.yml
x-coverage:
state: covered
reason: covered
detail: 'IIT Bombay is one of the few universities in this cohort with a genuine first-party API, and this run found it.
The InstiApp API is institution-hosted (gymkhana.iitb.ac.in), publishes an autogenerated 112-path specification at /docs/,
answers a substantial read surface with no credential, and carries an institutional contact and AGPL-3.0 public source
— captured here as an OpenAPI plus derived schema, vocabulary, ruleset, lifecycle and probed examples and errors. A second
institution-operated surface, the Computer Centre''s central OpenID Connect provider at sso.iitb.ac.in, publishes a live
discovery document and JWKS and was not previously catalogued. What IIT Bombay does NOT publish is equally settled and
stated rather than padded: no central developer portal, no course-catalog or registrar API (asc.iitb.ac.in is a single-sign-on
gate behind hCaptcha), no open-data portal (data.iitb.ac.in does not resolve), no research-computing or HPC surface (hpc./spacetime.
do not resolve), no library discovery API (opac.library.iitb.ac.in returns 502), no AI policy or AI-tooling statement
discoverable from the institutional site, and nine of the twelve education-regime domain standards produce no evidence
at all. One surface is genuinely blocked to us rather than absent: the Central Library DSpace OAI-PMH endpoint is denied
at the Apache layer (403) while the DSpace application itself is demonstrably alive, so oai-pmh conformance is recorded
as unverified, not false. No vendor contract was added and none was found attributed to this institution — the pre-run
audit reported no hostless, shared-contract or misbased findings, and none were discovered by hand.'
evidence:
- url: https://gymkhana.iitb.ac.in/instiapp/api/docs/?format=openapi
status: 200
- url: https://gymkhana.iitb.ac.in/instiapp/api/events
status: 200
- url: https://gymkhana.iitb.ac.in/instiapp/api/bodies
status: 200
- url: https://gymkhana.iitb.ac.in/instiapp/api/mess
status: 200
- url: https://gymkhana.iitb.ac.in/instiapp/api/locations
status: 200
- url: https://gymkhana.iitb.ac.in/instiapp/api/user-me
status: 401
- url: https://sso.iitb.ac.in/.well-known/openid-configuration
status: 200
- url: https://sso.iitb.ac.in/.well-known/jwks.json
status: 200
- url: https://sso.iitb.ac.in/token
status: 400
- url: https://gymkhana.iitb.ac.in/profiles/doc/
status: 200
- url: https://gymkhana.iitb.ac.in/profiles/oauth/token/
status: 405
- url: https://gymkhana.iitb.ac.in/profiles/user/api/user/
status: 401
- url: https://sso.tech-iitb.org/docs/
status: 200
- url: https://dspace.library.iitb.ac.in/oai/request?verb=Identify
status: 403
- url: https://dspace.library.iitb.ac.in/xmlui/OAI/request?verb=Identify
status: 200
note: Content-Length 0 — soft-200, dead
- url: https://www.library.iitb.ac.in/
status: 200
- url: https://asc.iitb.ac.in/
status: 200
note: SSO + hCaptcha gate
- url: https://www.iitb.ac.in/
status: 200
- url: https://www.iitb.ac.in/credits-disclaimer
status: 200
- url: https://github.com/DevCom-IITB
status: 200
- url: https://www.linkedin.com/school/indian-institute-of-technology-bombay/
status: 999
note: LinkedIn bot block — live
- url: https://data.iitb.ac.in/
status: 0
note: DNS does not resolve
- url: https://api.iitb.ac.in/
status: 0
note: DNS does not resolve
- url: https://hpc.iitb.ac.in/
status: 0
note: DNS does not resolve
- url: https://opac.library.iitb.ac.in/
status: 502
- url: https://www.iitb.ac.in/llms.txt
status: 404
- url: https://www.iitb.ac.in/.well-known/security.txt
status: 404
maintainers:
- FN: Kin Lane
email: kin@apievangelist.com
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we
store it to create your key and to recognise you if you sign in with another
provider. See our Privacy Policy and
Terms.